Supplier portal
An importer has to collect documentation, declarations and bills of materials from the upstream manufacturer. That is usually done by email, and the result is a folder of attachments nobody can trace any more. Here the supplier uploads them, in a portal that shows very little, and every document arrives marked with who brought it and when. The supplier states; verifying is your job.
Two screens, and a boundary between them
/fornitori, inside the application. From Products, the Suppliers button. It is reserved to the organisation's administrators: inviting an outsider to read your products' documentation is not an operational gesture./fornitore?t=…, at an address separate from the application's. Whoever enters has no account, no session and does not belong to your organisation: they have a link with a token, like anyone opening the public reporting form.The link to hand to the supplier is composed by the panel: copy it and send it as it is. Do not rebuild it by hand.
Inviting a supplier
| Field | What to enter |
|---|---|
| Name (required) | How you will recognise this supplier in the list. |
| Address (required) | A valid email address. It is how you know who you gave access to. |
| Type | Component supplier, upstream manufacturer, importer, distributor, evidence provider. A closed list. |
| Shared products (at least one) | Active managed products only, and only yours. An invitation with no products gives access to nothing and is refused. |
| Duration | 7, 30, 90 or 180 days. |
The token appears once only. Of that link the system keeps only its fingerprint: it does not reach a log, a registry row, or an email we can re-read. If it is lost it cannot be recovered — revoke the invitation and issue another. That is the intended behaviour, not a limitation.
A variant is not shared on its own, and an archived product is no longer in the active perimeter: both stay out of the shareable list.
Asking for a document
On any active invitation you can open a request: a product among the shared ones and a line of text saying what you need. The request appears in the supplier's portal under "What has been asked of you", and when they deposit a document answering that request the state advances by itself to document received — and stops there.
Only your organisation writes the last three. There are no states such as "manufacturer compliant": that is a conclusion, and it does not come out of a portal.
What arrives is quarantined
A document deposited by a supplier is a file sent by an outsider, and it gets the same treatment as attachments from the public reporting form.
An uploaded document is not an accepted document. What arrives is born "to be reviewed" and no path on this surface moves it to "reviewed": that step is a gesture by a person in your organisation. That is how the Regulation distributes responsibilities, and software that compressed them would move them onto whoever does not hold them. See CRA controls and evidence.
What the supplier sees
Their name, your organisation's name, the expiry date of the access, the products you shared with them, the requests assigned to them, and what they uploaded themselves. Nothing else: not the product register, not the cases, not the other suppliers, not the registry. The portal is not indexable and is not cached.
An unknown, expired or revoked link gets the same answer: "this link does not open anything". Distinguishing the three cases would tell whoever is trying whether a token ever existed.
Revoking
The revoke button closes the door immediately, not at the token's expiry: from the next use that link does not pass. Access removed "sooner or later" is not access that has been removed. Documents already deposited remain — they are dossier material — and stay downloadable from your panel.
In the list every invitation carries its own state — active, revoked or expired — and revoked invitations stay visible: you need to be able to say "this access is closed", and who closed it.
What goes into the registry
Issuing an invitation, revoking it, opening a request, updating it, and the arrival of a document each leave a row in the activity registry. The plaintext token and the supplier's address do not: the first is a secret, the second is personal data that an evidence package does not need.